Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

Enforcement of the Massachusetts Data Privacy Law

Posted on August 30, 2011August 24, 2011 by Doug Cornelius
Print Friendly, PDF & Email

It’s been almost 18 months since the Massachusetts Data Privacy Law went into effect. Belmont Savings Bank has become one of the first charged with violating the law.

Belmont Savings Bank maintained personal information on an unencrypted backup data tape and then lost the tape. According to surveillance footage the tape was likely discarded inadvertently by the overnight clearing crew and sent to the incinerator.

There were several rounds of changes between the first version of 201 CMR 17.00 and the final one. One central element was the requirement that there be written information security plan in place if your company has “personal information” on a Massachusetts resident. Obviously, you need to comply with the plan.

In this case, Belmont Savings Bank has the plan. But they failed to comply with it. The data tape should have been locked-up overnight and not left on a desk.

The Massachusetts’ Attorney General entered into an Assurance of Discontinuance with Belmont Savings Bank. As part of the settlement, the bank has to

  • encryp, to the extent technically feasible, all personal information stored on backup data tapes
  • store backup data tapes containing personal information in a secure location
  • effectively train its workforce on the policies and procedures with respect to maintaining the security of personal information

There is no evidence indicating that any customer’s personal information has been acquired or used by an unauthorized person or used for an unauthorized purpose. The Assurance of Discontinuance states that if actual harm to customers results, the Attorney General’s Office will reopen discussions to determine appropriate restitution.

Sources:

  • Massachusetts Attorney General Announces $7,500 Data Breach Settlement with Belmont Savings Bank in Hunton & Williams’ Privacy and Information Security Law Blog
  • Massachusetts AG Says Having a WISP is Not Enough to Comply With Massachusetts Data Security Regulations by Amy Crafts in Proskauer’s Privacy Law Blog
  • Assurance of Discontinuance in the Matter of Belmont Savings Bank (.pdf – 5 pages)
  • Today is the Deadline for the Massachusetts Data Privacy Law – prior story in Compliance Building

Share this:

  • Print (Opens in new window) Print
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on X (Opens in new window) X
  • Email a link to a friend (Opens in new window) Email

2 thoughts on “Enforcement of the Massachusetts Data Privacy Law”

  1. Theresa Hamacher says:
    August 30, 2011 at 12:11 pm

    An important reminder that it’s important to follow procedures — not just have them. Thanks for keeping us up to date. Data security and privacy are high priority for NICSA members.

    Reply
  2. Pingback: Weekly Top Story Digest - August 31, 2011 | ComplexDiscovery

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search for Stuff

Recent Stories

  • When the Lawyer Is Breaking Bad
  • Will Investors Have an Appetite for Semi-Annual Reporting?
  • Special Forces Trading on Insider Knowledge
  • Prediction Markets and Compliance Programs
  • The One with the Line That Goes Straight Up and Right
  • The One with the Crypto Paying for a Mega-Shilling Package
  • The Performance of the SEC in 2025
  • More on the Downsizing of the SEC
  • SEC Enforcement Results for FY 2025
  • Proposed Fundamental Reforms to AML Programs

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.